Introduction

DeepSeek Harness (DSH) adopts an “everything is a plugin” architecture, which means that most core runtime capabilities are provided by various plugins. Managing these plugins traditionally requires restarting the application or manually editing configuration files, which is not intuitive and can be error-prone. dsh-plugin-manager aims to solve this problem by providing a Web interface that lets you directly enable or disable installed plugins from the settings page, while automatically handling writes to the underlying configuration files.

Feature Overview

The runtime entry ID of this plugin is dsh-plugin-manager. Its core features include:

  • Web settings page management: Provides a plugin list in the Web settings page, with support for search and filtering (Official / Third-party). Each plugin has a toggle switch, and changes take effect immediately.
  • Configuration persistence: Enable/disable operations automatically write to the user-level cordis.patch.yml file, ensuring that the state is preserved after a restart.
  • Hot reload support: Uses the hot reload mechanism of the Cordis loader, so enable/disable operations do not require restarting the process.
  • Status display: Shows plugin runtime states (Running / Disabled / Mount failed, etc.), official badges (@deepseek-ai/*), and protection markers.
  • Security protection: Includes a trusted request fence to prevent cross-site request forgery and DNS rebinding attacks, restricting the configuration plane to loopback addresses.
  • Core protection: Uses a built-in protection list to prevent disabling core entries such as webserver, ui-settings, and ui-sidebar, avoiding UI self-lockout.

Installation and Enablement

Installing this plugin requires the DSH plugin command-line tool.

dsh plugin --profile web add @wsgsety/dsh-plugin-manager

After installation, you need to restart the DeepSeek Harness Web profile (via the command line or the desktop app) for the plugin to take effect.

Usage

After successful installation, navigate to “Plugins > Plugin Manager” in the settings page of the Web interface.

  • Search and filter: Enter keywords in the search box to quickly locate plugins. You can filter by the “Official” or “Third-party” label.
  • Enable/disable plugins: Click the toggle on the right side of a plugin row to enable or disable it. Enabling a plugin writes disabled: false; disabling a plugin writes disabled: true. Changes are automatically saved to the user patch layer.

Architecture and Security

The plugin interacts with the DSH backend through custom routes.

Route Design

Route Method Description
/dsh-plugin-manager/entries GET Fetch loader entry projections and the patch disabled list
/dsh-plugin-manager/set-enabled POST Execute enable/disable operations and persist them via patch writing
/dsh-plugin-manager/ping GET Health check

Trusted Request Fence

All endpoints use the same trusted request fence as the official dsh-client-connection:

  • Host validation: Requests must be sent to a loopback authoritative address (localhost / 127.0.0.0/8 / [::1]).
  • Request source: Rejects requests with Sec-Fetch-Site: cross-site.
  • Origin consistency: The Origin header provided by the request must exactly match the Host header.
  • Write interface restrictions: Write endpoints additionally require the visible TCP peer address to be a loopback address, restricting the configuration plane to the local machine.

Protection Mechanism

The plugin itself and DSH core entries are protected and cannot be disabled. The protected list includes but is not limited to:

webserver, web-runtime, modules, connection, client-runtime, locale, ui-layout, ui-sidebar, ui-settings, ui-settings-plugins (the owner of the page slot used by this plugin), settings, typert*, api-remotes, dsh-plugin-manager.

Notes

  • Patch layer semantics: The layering rules of cordis.patch.yml require the disabled field to be written explicitly. Disabling a plugin requires writing disabled: true; enabling a plugin requires writing disabled: false. Deleting this field or writing a non-boolean value will cause the plugin to be disabled again after a restart or may result in parsing failure.
  • Request body size limit: Write requests have a limited JSON body size (16 KiB), which limits concurrent operations that modify a large number of plugins at once.
  • Network restrictions: The plugin only supports access via loopback addresses. The management interface cannot be accessed through a LAN IP or a public IP.
  • Dependency: This plugin depends on @deepseek-ai/cordis as a peer dependency.